A publicly invokable serverless function with broad IAM permissions shows a sudden spike in invocation rate and increasing execution errors over the past hour. What are the two most critical immediate containment actions?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AArchiving logs and metrics matters for the investigation, but on its own it does nothing to stop the abuse that is happening right now.
- BRotating credentials is an important follow-up once you suspect exposure, but it does not stop the public endpoint from being invoked in the meantime.
- CFlow logs and IP blocks are weak containment for a public serverless function, whose callers rotate addresses easily and do not traverse a VPC you control.
- DCorrect: removing public invoke permission cuts off the attacker's entry point, and preserving logs and telemetry keeps the evidence needed to scope what happened.